A digital signature is a number computed from two things: the message being signed and the private key. Anyone holding the matching public key can check that the signature fits the message, and nobody can produce a valid one without the private key.
Bound to one message
A signature is valid for one exact message. In Bitcoin the message is the transaction itself. If someone changes the amount or the destination, the signature no longer matches and every node rejects the transaction. A signature can be copied, but it cannot be reused on another payment.
The maths behind it
Bitcoin keys live on an elliptic curve called secp256k1. Signatures were made with ECDSA from the start. Since the Taproot upgrade in 2021, a second scheme is also used: Schnorr signatures, simpler and able to combine several signatures into one.
▶ SEE IT IN THE MACHINEIn the WALLET, the sealed key signs the payment; only the signature leaves the safe.